Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56353

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 1.123.22 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия от 2.0.0 (включая) до 2.9.3 (исключая)
cpe:2.3:a:n8n:n8n:2.10.0:*:*:*:community:node.js:*:*
cpe:2.3:a:n8n:n8n:2.10.0:*:*:*:enterprise:node.js:*:*

EPSS

Процентиль: 26%
0.0033
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.8
github
около 2 месяцев назад

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

EPSS

Процентиль: 26%
0.0033
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-287